CWE-268: Privilege Chaining
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-7973 — Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
- CVE-2025-64701 — QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user
- CVE-2025-2903 — Privilege Chaining in Delphix
- CVE-2026-3888 — Local Privilege Escalation in snapd
- CVE-2025-2297 — Privilege Management for Windows - Elevation of Privilege
- CVE-2025-0889 — Privilege Management for Windows – Elevation of Privilege
- CVE-2026-32325 — Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit
- CVE-2024-1250 — Privilege Chaining in GitLab
- CVE-2024-1299 — Privilege Chaining in GitLab
- CVE-2025-32955 — Harden-Runner Evasion of 'disable-sudo' policy
- CVE-2025-36124 — IBM WebSphere Application Server Liberty bypass security
- CVE-2025-20112 — Cisco Unified Communications Products Privilege Escalation Vulnerability
- CVE-2024-4877 — OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi
- CVE-2024-47045 — Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited,
Recently published
- CVE-2026-32325 — Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit
- CVE-2026-3888 — Local Privilege Escalation in snapd
- CVE-2025-64701 — QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user
- CVE-2025-7973 — Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
- CVE-2025-36124 — IBM WebSphere Application Server Liberty bypass security
- CVE-2025-2297 — Privilege Management for Windows - Elevation of Privilege
- CVE-2025-20112 — Cisco Unified Communications Products Privilege Escalation Vulnerability
- CVE-2025-32955 — Harden-Runner Evasion of 'disable-sudo' policy
- CVE-2025-2903 — Privilege Chaining in Delphix
- CVE-2024-4877 — OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi
- CVE-2025-0889 — Privilege Management for Windows – Elevation of Privilege
- CVE-2024-47045 — Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited,
- CVE-2024-1299 — Privilege Chaining in GitLab
- CVE-2024-1250 — Privilege Chaining in GitLab